THREAT OPS › Threat News › [NVD] CVE-2026-40175 (MEDIUM 4.8) — Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound
[NVD] CVE-2026-40175 (MEDIUM 4.8) — Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound
CVE-2026-40175 CVSS: 4.8 MEDIUM Published: 2026-04-10T20:16:22.800
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and
Indicators of compromise
- CVE-2026-40175cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40175